15 sep
|
Giesecke u0026 Devrient GB
|
Barcelona
15 sep
Giesecke u0026 Devrient GB
Barcelona
The role of Security Manager Azure will help shape G+D Mobile Security's future in IoT security. G+D combines digital security, financial platforms, and currency technology with a general reach of 14,000 employees. Own and continuously improve our ISMS, policies, and security governance lifecycle.
Lead security risk assessments, maintain the risk register, and drive quarterly risk cycles. Ensure operational compliance with ISO 27001:2022, GSMA SAS, NIS-2, and customer security requirements; support hands‐on configuration tasks. Collaborate with the Security Architect to connect governance with DevSecOps and cloud practices.
Own Azure security posture, govern Microsoft Defender for Cloud findings, Entra ID Conditional Access policies, Privileged Identity Management (JIT access), and quarterly access reviews. Support cross‐platform governance tasks, policy alignment, and shared risk register entries covering AWS and Azure workloads.
Enforce Zero
Trust controls across cloud environments: continuous verification, least‐privilege access, and RBAC/ABAC enforcement.
Govern IaC and CI/CD pipeline security gates: review IaC templates for secrets management compliance, approve pipeline security controls, and validate rollback procedures. Produce structured assurance reporting for management: metrics tied to the risk register, control effectiveness, and remediation tracking for findings from Defender for Cloud and AWS Security Hub. At least 5 years in information security, risk, audit, or compliance,
with a minimum of 3 years in a similar role (security management, cloud security governance, or ISMS ownership), ideally in regulated environments (telecommunications, banking, payments, SaaS).
Strong understanding of ISO 27001, risk methodologies, and modern security frameworks. Solid knowledge of security controls (IAM, third‐party risk, secure SDLC, cloud). Solid knowledge of Azure and AWS security controls.
Familiarity with IaC security practices: secrets management, pipeline approval workflows, and dependency vulnerability handling.
Experience producing security assurance metrics and governance reports for senior stakeholders.
Fluent
English; German or Spanish is a plus. AZ-500 (Microsoft Certified: Azure Security Engineer Associate) AWS Certified Security–Specialty CCSK (Certificate of Cloud Security Knowledge) Familiarity with the Microsoft Cloud Security Benchmark (MCSB) or CIS Benchmarks for Azure / AWS Global Collaboration: work collaboratively with stakeholders around the globe.
Career Development: continuous training, coaching, and talent development programs. Work‐Life Balance: flexible working hours with the option for remote work. We warmly welcome all applications regardless of gender, age, race or ethnic origin, social and cultural background, religion, disability, sexual orientation. The personal data you provide will be processed to manage your application in accordance with the GDPR and our Privacy Policy.
📌 Security Manager Azure (Barcelona)
🏢 Giesecke u0026 Devrient GB
📍 Barcelona